Document Title: =============== Syneto UTM WAF v1.4.2 - Multiple Web Vulnerabilities References (Source): ==================== http://www.vulnerability-lab.com/get_content.php?id=373 Release Date: ============= 2012-01-20 Vulnerability Laboratory ID (VL-ID): ==================================== 373 Product & Service Introduction: =============================== The Syneto UTM (Unified Threat Management) is a security appliance that performs multiple functions and delivers maximum protection against internet threats. It s a single device that has it all: firewall, gateway antivirus and anti-spam, VPN, content filter, multiple gateways and on-appliance reporting. Syneto UTM was specifically designed to easily be deployed and managed, supply top protection and save you money. (Copy of the Vendor Homepage: http://syneto.net/en/network-security/utm) Abstract Advisory Information: ============================== A Vulnerability-Lab researcher discovered multiple web vulnerabilities on Synetos Security UTM Application v1.4.x & v1.3.3 CE. Vulnerability Disclosure Timeline: ================================== 2011-10-07: Vendor Notification 2012-**-**: Vendor Response/Feedback 2012-**-**: Vendor Fix/Patch 2012-01-20: Public or Non-Public Disclosure Discovery Status: ================= Published Exploitation Technique: ======================= Remote Severity Level: =============== High Technical Details & Description: ================================ 1.1 Multiple persistent web vulnerabilities are detected on the Syneto Unified Threat Management Security Appliance Application. The vulnerability allows an privileged user account to inject malicious persistent script code on application-side(server). Successful exploitation of the vulnerability can result in account steal, persistent session hijacking via script code inject, persistent external redirects, persistent context manipulation on requests & persistent phishing. Vulnerable Module(s): [+] Reports => Executive Summery => Name Input Fields & Output Listing Category [+] EMail => Filter Add or Configure Edit [+] EMail => Add Blacklist Rule & Add Whitelist Rule [+] EMail Settings - New Domain Picture(s): ../1.png ../2.png 1.2 Multiple non-persistent cross site scripting vulnerabilities are detected on the Syneto Unified Threat Management Security Appliance Application. The vulnerability allows remote attacker to hijack customer/admin sessions via client side cross site scripting requests. Successful exploitation requires user inter action & results in account steal via session hijacking. Vulnerable Module(s): [+] Index - Exception Handling via Errors [+] Index - Info Requests Affected Version(s): [+] Synetos Security UTM Application v1.4.x & v1.3.3 Community Edition Proof of Concept (PoC): ======================= The vulnerabilities can be exploited by privileged user accounts, lowviewers or remote attackers with required user inter action. For demonstration or reproduce ... 1.1.1 [+] Reports - Executive Summery - Output Listing Category
Status | Domain | Routing | Verify sender | Send digest | Actions |
---|---|---|---|---|---|
" type="hidden">
![]() |
"> | Reference(s): https://[SYNETO UTM SERVER].com/syneto.php?menuid=60 1.2 PoC: https://[SYNETO UTM SERVER].com/index.php?error=need_login"'>